A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2007 | A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server. |
Github GHSA |
GHSA-7rp6-w7mg-h8rw | XML External Entity Reference in Apache Jena |
Fixes
Solution
No solution given by the vendor.
Workaround
Users are advised to upgrade to Apache Jena 4.2.0 or later.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T02:06:40.799Z
Reserved: 2021-08-17T00:00:00
Link: CVE-2021-39239
No data.
Status : Modified
Published: 2021-09-16T15:15:07.527
Modified: 2024-11-21T06:18:59.310
Link: CVE-2021-39239
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA